Follow by email allows for following by unverified emails
Low
A
Automattic
Submitted None
Team Summary
Official summary from Automattic
The initial report outlined being able to add any email to a Tumblr account without verifying it first which is expected behavior that does not pose a security risk. However, the reporter also reported that these unverified emails were able to be used in our “follow by email” feature which we did consider to be a security risk. Our fix was to disallow follow by email for unverified emails.
Actions:
Reported by
myominthu_sec
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Violation of Secure Design Principles